Plugins Docs Blog My licences Let's talk

YouTube videos, Google Maps and Google Fonts on WordPress under the GDPR

Cookie ConsentUpdated 4 October 20264 min read

Cookie Consent

A YouTube video, a Google Map or a Google Font embedded in a WordPress page contacts Google's servers as soon as the page opens, before the visitor has done anything. That request carries the visitor's IP address, and the embed can set cookies or local storage. Under the GDPR, this needs consent. The fix is to show a placeholder box with a button, and load the real embed only when the visitor clicks it or accepts the category.

This guide explains why each of the three is a problem, what the "privacy-enhanced" options really change, and how to keep your videos and maps without sending data before consent.

Why embeds are a GDPR issue

When a page contains an <iframe> from youtube.com or google.com/maps, the visitor's browser downloads it from Google. Google receives the IP address, the page address and the browser details, and the embedded player or map runs Google's own scripts, which can store identifiers on the device.

The IP address is personal data. The ePrivacy rules require consent for storing or reading information on the device unless it is strictly necessary, and an embedded video the visitor has not asked to play is not strictly necessary for the page. So the embed should wait.

The Google Fonts ruling

The clearest example comes from Germany. On 20 January 2022 the Regional Court of Munich (LG München I, 3 O 17493/20) ordered a website owner to pay 100 euros in damages to a visitor, because the site loaded Google Fonts from Google's servers and so passed the visitor's IP address to Google without consent. The court noted that the site could have hosted the fonts itself (summary by Kanzlei Plutte, in German).

The amount was small. What followed was not: thousands of warning letters were sent to German site owners in 2022 demanding payment for the same issue. The lesson holds for every embed: if a resource comes from a third party and is not needed, it either waits for consent or moves onto your own server.

Is youtube-nocookie.com enough?

YouTube offers a "privacy-enhanced mode": you change the embed address from youtube.com to youtube-nocookie.com. According to YouTube's help page, views in this mode do not influence the viewer's YouTube experience and the ads shown are non-personalised.

That is useful, but it does not solve the consent question:

  • the browser still contacts Google servers when the page loads, with the visitor's IP address;
  • the player still runs Google's scripts and can store data on the device once the video plays;
  • YouTube itself warns that clicking out of the embed leads to sites with their own tracking.

Use the nocookie address, and still hold the video back until consent.

Google Maps

An embedded map works the same way: an iframe from Google that loads Google's scripts. For a contact page, you have three options:

  1. Placeholder with a button. The map loads only when the visitor clicks "Show map".
  2. A static image and a link. A screenshot of the map, linked to Google Maps. Nothing loads until the visitor leaves your site by choice.
  3. Address only. Often the address, opening hours and a "Get directions" link are what people really need.

How a good placeholder works

The pattern that solves all of this is called click-to-load, or two-click. Instead of the video, the visitor sees a box of the same size with:

  • the name of the provider, for example "YouTube";
  • one sentence on what happens if they load it ("This video is hosted by YouTube, which may set cookies");
  • a button to load it now.

Clicking the button is a clear, specific action, so it can count as consent for that category. The page keeps its layout, the visitor keeps the choice, and the video is one click away instead of gone.

Doing it on WordPress

WordPress turns a pasted YouTube link into an embed automatically, and page builders add maps with a widget, so the iframes come from many places: the block editor, Elementor, the theme, a plugin. Replacing each one by hand is slow and breaks the next time someone pastes a link.

Cookie Consent handles it on the server. Before the page is sent, it finds iframes and scripts from YouTube, Vimeo, Google Maps and the other services it knows, and replaces each one with a box showing the provider name and a load button. When the visitor accepts the category, in the banner or in the box, the real embed comes back without reloading the page.

WordPress page where an embedded YouTube video is replaced by a Cookie Consent box titled Content blocked, naming YouTube, with a Load this content button
A blocked video: same size as the player, provider name and one button.

Google Fonts are recognised too, and listed in the Preferences category, with a note suggesting to host them yourself, which is still the best fix. To change the text in the box, see Texts and languages; to find embeds you did not know about, run the scan described in Third parties and scan.

Checklist for embeds

  • Google Fonts and other font services: hosted on your own server.
  • YouTube and Vimeo: nocookie address where possible, and a placeholder until consent.
  • Google Maps: placeholder, static image or a simple link.
  • Each embed listed in the cookie policy with its provider.
  • Test in a private window: no request to youtube.com, google.com/maps or fonts.googleapis.com before a choice.

For the rest of the banner, from the Reject button to the consent log, see GDPR cookie banner for WordPress.

Frequently asked questions

Do I need consent to embed a YouTube video?

In the EU, yes in practice. The embed contacts Google as soon as the page loads and can store identifiers on the device. Show a placeholder and load the video after the visitor clicks or accepts the category.

Does youtube-nocookie.com make the embed GDPR compliant?

Not on its own. Privacy-enhanced mode limits how YouTube uses the view, but the browser still contacts Google with the visitor's IP address and the player can store data once the video plays.

Are Google Fonts allowed under the GDPR?

Loading them from Google's servers without consent was ruled unlawful by the Munich Regional Court in January 2022. Hosting the font files on your own server solves the problem and needs no consent.

Can a click on the video placeholder count as consent?

Yes, if the box says clearly which provider will load and what that means. Clicking the button is a specific, informed action for that category.